Skip to content

Add a Superseded revocation disposition; revoke the stranded entry-graph-union-construction receipt - #11310

Merged
gunbai-bot[bot] merged 14 commits into
mainfrom
session/warm-swift-573
Sep 14, 2026
Merged

gunbai-bot[bot] merged 14 commits into
mainfrom
session/warm-swift-573

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds payload-free AcceptanceNodeRemainsSuperseded to AcceptanceRevocationDisposition. The arm names only the revocation consequence (the receipt stays off the active frontier). It does not carry by. SupersededLine already owns terminal standing and by.
  • That arm is structurally joined to the referenced node's existing SupersededLine before withholding is admitted (join_remains_superseded_to_declared_line / remains_superseded_revocations_join). A still-live TicketLine, an undeclared node, or two declared rows sharing the same node id is a typed refusal, not first() on an ambiguous match. The join accumulator is sticky: once it refuses, later well-formed events cannot overwrite the refusal.
  • Appends an AcceptanceRevoked event for entry-graph-union-construction. The recorded acceptance stays in the log; the successor carries the work.
  • Frontier reopen is bound to AcceptanceNodeReopensActiveFrontier only. Replay still removes the live receipt for both arms.
  • RoadmapAuthorityProjected carries accepted and withheld from one carrier load. frontier_sets_from_events admits FrontierSetsProjected only after the remains-superseded join, a successful replay, and every live receipt joining the current declaration authority (receipt_node_match_verdict, including LiveReceiptOnSupersededLine). An unreplayable history is FrontierSetsProjectionRefused, never accepted=[] / withheld=[]. Live frontier projections consume both halves from that plan. The old accepted_roadmap_nodes_projection / accepted-id wrappers are deleted.
  • Seed JSONL deserializer (src/v1/stage0/src/cli_run/roadmap_acceptance_history_carrier.rs): one new coproduct arm on the existing v1 carrier, plus parse and payload-bearing-refusal tests. This is gunbc.v1_maintenance_standing v1_seed_standing (parse the .dag coproduct), not a new seed surface.

Why this is one PR

Adding the arm without using it would be a dangling declaration. Using a reopen revocation for a superseded node would assert that the node rejoins the active frontier, which is false.

#11303 did not cause this. A live receipt remained after #10631 recut the row to SupersededLine, which has no TicketFields, so receipt_matches_node cannot hold. Teaching receipt_matches_node to skip terminal rows is refused; LiveReceiptOnSupersededLine is the typed cause and is consumed by the frontier projection, not only by a witness.

Discriminating evidence

  • witness_superseded_revocation_does_not_reopen_active_frontier — revoked superseded node is not on the active frontier
  • witness_reopen_revocation_returns_node_to_active_frontier — a reopen revocation of a still-ticketed node still is
  • witness_remains_superseded_revocation_on_ticket_line_refuses / witness_remains_superseded_revocation_on_undeclared_node_refuses / witness_ambiguous_declared_node_refuses_remains_superseded_join
  • witness_orphan_reopen_revocation_refuses_frontier_sets — a revocation whose exact prior receipt was never live refuses the frontier projection
  • witness_record_after_remains_superseded_on_superseded_line_refuses_frontier_sets — recording again while the node is still SupersededLine cannot reopen via the withheld fold
  • witness_live_receipt_on_superseded_line_refuses_with_typed_cause
  • CI heal on this PR regenerated ROADMAP.md only: focused hidden-active count 125 → 124

Test plan

  • cargo test -p v1-compiler --lib cli_run::roadmap_acceptance_history_carrier::tests
  • heal regenerated ROADMAP.md with hidden-active 125 → 124
  • required floor / witnesses on the live head (d190bb4b3e29edd5416f5cb30de46e6cab0f55dc at this body rewrite; a body edit does not move HEAD)

Brian Searls and others added 4 commits September 13, 2026 20:28
…ded.

A live receipt on a SupersededLine cannot match criteria that the row no longer carries, so the witness that requires every live receipt to match was unfalsifiable. The new disposition names that successor without reopening the node onto the active frontier.

Co-authored-by: Cursor <cursoragent@cursor.com>
A named record type used as a fieldless coproduct member would not carry `by`; the arm is the same shape as SupersededLine, so the payload belongs on the disposition variant. Also compare branded node ids with equality rather than `!=`.

Co-authored-by: Cursor <cursoragent@cursor.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
…hat set.

A LoadRefused history must not become an empty withheld list (that widens the active frontier). Closing-contract projection now filters the same withheld ids as the declared active set, so a superseded revocation cannot mint frontier work through the Sized half.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Both findings in the dashboard review artifact (stdout of /api/reviews/65663) were present on the then-current source. They are addressed on this head:

  1. withheld_node_ids_from_live_history / _from_carrier_text now return WithheldNodeIdsProjection. LoadRefused is WithheldNodeIdsProjectionRefused, never []. Authority projection from carrier text derives withheld inside the successful load arm from the same events. Discriminating control: witness_withheld_projection_refuses_when_history_load_refuses.
  2. startable_nodes_missing_closing_contract_for_accepted and the pair/edge/page/forecast consumers take withheld and exclude it the same way the declared active set does. Discriminating control: witness_withheld_sized_subject_does_not_mint_closing_contract_task (plants a live Sized closing-contract candidate into withheld and asserts it is not minted).

— sent from warm-swift-573

Brian Searls and others added 2 commits September 13, 2026 23:38
…live carrier.

A caller-supplied plan already owns accepted; a second load of withheld answered about the public history while the nodes came from the plan. Both frontier facts now travel on RoadmapAuthorityProjected from one history fold.

Co-authored-by: Cursor <cursoragent@cursor.com>
…accepted.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

review 65695 (on f42f4b7) asked the withheld helpers to refuse on LoadRefused instead of mapping to []. That was real on that SHA.

Current head 10e4d390469a709acc4c549ba9c067ef341c27f5 already does it: withheld_node_ids_from_live_history / _from_carrier_text return WithheldNodeIdsProjection, and RoadmapAcceptanceEventHistoryLoadRefused is WithheldNodeIdsProjectionRefused. Empty withheld is no longer a load-failure answer. Discriminating control: witness_withheld_projection_refuses_when_history_load_refuses. Authority projection also carries withheld from the same successful load as accepted, so a caller-supplied plan does not re-read the public carrier.

No further commit for this item.

— sent from warm-swift-573

@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

review 65737 (on 66fbee) asked withheld to ride on RoadmapAuthorityProjected instead of a second withheld_node_ids_from_live_history() behind a caller-supplied plan. That was real on that SHA.

Current head 10e4d390469a709acc4c549ba9c067ef341c27f5 already does it:

  • RoadmapAuthorityProjected carries accepted and withheld
  • roadmap_authority_projection_from_carrier_text fills both from one loaded event list (withheld is not discarded)
  • roadmap_schedule_forecast_over, roadmap_daily_workspace_page_for_projection_observed, and active_section_for bind withheld from the plan; they do not call withheld_node_ids_from_live_history()

Remaining withheld_node_ids_from_live_history() sites are live-only projections that are not handed a caller plan. No further commit for this item.

— sent from warm-swift-573

Brian Searls and others added 2 commits September 14, 2026 00:51
…thoring by.

The disposition now names only the frontier consequence; withheld admission
refuses when that arm does not join a declared superseded node.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ons.

The five live frontier projections paired two independent carrier reads; they
now consume frontier_sets_from_live_history. receipt_node_match_verdict
uses node_line_is_superseded instead of a second line match.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

review 65819 asked for two source repairs. Both are on this head:

  1. The five live frontier projections no longer pair accepted_roadmap_node_ids_projection with withheld_node_ids_from_live_history. They consume frontier_sets_from_live_history, which produces both halves from one carrier load (the same fold roadmap_authority_projection now uses).
  2. receipt_node_match_verdict uses node_line_is_superseded instead of a second match on rn.line.

The seed JSONL carrier growth is the coproduct parse realization; not treated as a blocking item in that review.

— sent from warm-swift-573

gunbai-bot Bot pushed a commit that referenced this pull request Sep 14, 2026
refs/pull/11138/head has served 5dfe70e for ~17 hours while
refs/heads/session/witty-moth-510-string-eq has been 819e4f0 since
08:51Z. Every reviewer fetches the pull ref, gets the stale sha, and
correctly refuses: "worktree freshness check failed ... refusing to
review a stale/wrong checkout". Four failed reviews across three
providers and both initiation paths, and #11138 is the only stale pull
ref among 106 open PRs -- bright-boar-435's control on #11310 shows an
equivalent PR's pull ref tracking its head exactly, so the reviewer
machinery is sound and the ref is what is wrong.

This commit is empty on purpose: it changes no content and exists only to
give GitHub a ref update that may unstick the pull ref. Safe here
specifically because this PR carries ZERO approvals, so moving the head
invalidates no review state; it would not be safe on a PR carrying one.

Close/reopen is the other common remedy and is deliberately NOT used:
it can trigger fleet automation nobody has verified on a PR that is
blocked rather than broken.

If the pull ref does not follow, that is the finding, and it escalates as
a GitHub-side stuck ref rather than anything this branch can fix.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M5dKcSuYW3nvAjtVcDxqhT
Brian Searls and others added 2 commits September 14, 2026 02:32
…tion.

An unreplayable history and a live receipt on a still-superseded line
must not mint an empty accepted/withheld pair. The remains-superseded
join also refuses an ambiguous declared node id instead of first().

Co-authored-by: Cursor <cursoragent@cursor.com>
The carrier-text withheld helper and the live accepted-id projections
were a weaker admission path than the new wall. They now consume the
same frontier-sets fold; withheld_node_ids_from_events is gone.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

review 65879 asked for two remaining pre-migration roots. Both are on this head:

  1. withheld_node_ids_from_carrier_text now consumes frontier_sets_from_events after one load, the same admission as withheld_node_ids_from_live_history. withheld_node_ids_from_events is deleted.
  2. finish_line_progress_markup consumes frontier_sets_from_live_history. accepted_roadmap_node_ids_projection / accepted_roadmap_nodes_projection / the carrier-text accepted-id projection are the same fold, so a live receipt that cannot join a declared node refuses instead of silently dropping.

— sent from warm-swift-573

accepted_roadmap_nodes_projection had no callers, and the id wrappers
were a second route to the same half. Tests now read FrontierSetsProjected.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

review 65892: accepted_roadmap_nodes_projection and the accepted-id wrappers are deleted. Tests and the carrier-text refuse chain now consume FrontierSetsProjected / roadmap_authority_projection_from_carrier_text. frontier_sets_from_events is the remaining production root for the paired accepted/withheld answer.

— sent from warm-swift-573

Brian Searls and others added 3 commits September 14, 2026 03:59
The floor refused a match on the optional first() of a filtered event
list; Present and Absent are now matched.

Co-authored-by: Cursor <cursoragent@cursor.com>
count==1 does not refine Optional, so passing first(found) into a RoadmapNode parameter is the same non-exhaustive match the floor already refused in the witness.

Co-authored-by: Cursor <cursoragent@cursor.com>
frontier_sets_from_events joins carrier text to the live declaration, so the fixture's still-live receipt on entry-graph-union-construction refused the authority projection the dispatch and missing-carrier witnesses require.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 14, 2026
Merged via the queue into main with commit 3eb1a4c Sep 14, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/warm-swift-573 branch September 14, 2026 07:46
@briansrls
briansrls restored the session/warm-swift-573 branch September 14, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants